https://www.forbes.com/sites/zakdoffman/2024/12/13/microsoft-confirms-password-deletion-for-1-billion-users-attacks-up-200/ Subscribe To Newsletters BETA THIS IS A BETA EXPERIENCE. OPT-OUT HERE Edit Story ForbesInnovationCybersecurity Microsoft Confirms Password Deletion For 1 Billion Users--Attacks Up 200% Zak Doffman Contributor Opinions expressed by Forbes Contributors are their own. Zak Doffman writes about security, surveillance and privacy. Following Dec 13, 2024,11:32am EST * Share to Facebook * Share to Twitter * Share to Linkedin New password changes come as attacks surge CFOTO/Future Publishing via Getty Images Microsoft has confirmed plans to delete passwords for a billion users. "The password era is ending," it says, warning those users that "bad actors know it, which is why they're desperately accelerating password-related attacks while they still can." The company now "blocks 7,000 attacks on passwords per second... almost double from a year ago." It has also seen adversary-in-the-middle phishing attacks increase by 146% year over year." All of which is bad news. But there's good news to come, it says, "we've never had a better solution to these pervasive attacks: passkeys." ForbesTikTok Ban--Change Your Account Before It's Too LateBy Zak Doffman In a blogpost published on Thursday, Microsoft sets out the ways in which it plans to "convince a billion users to love passkeys," through insightful design. "Passkeys not only offer an improved user experience by letting you sign in faster with your face, fingerprint, or PIN, but they also aren't susceptible to the same kinds of attacks as passwords. Plus, passkeys eliminate forgotten passwords and one-time codes." Passkeys have been accelerating in adoption this year. "In the two years since passkeys were announced and made available for consumer use, the FIDO Alliance reported a few weeks ago, "passkey awareness has risen by 50%, from 39% familiar in 2022 to 57% in 2024." MORE FOR YOU Can Trump Privatize The Postal Service? What To Know As President-Elect Says He's 'Looking At' USPS Changes Waymo Robotaxis Are Heading To Tokyo For Their First Overseas Road Tests Mystery Drones Over New Jersey And Nearby States: Trump Claims The Military Knows What The Sightings Are (Updated) And just like Microsoft, ease of use it says is important as improved security. "The majority of those familiar with passkeys are enabling the technology to sign in... Meanwhile, despite passwords remaining the most common way for account sign-in, usage overall has declined as alternatives rise in availability." Journey to a passwordless future Microsoft Microsoft's blogpost is all about furthering that adoption curve, because as ever it will be the last 30-40% of users that will be the hardest to convince. "Somehow, we had to convince an incredibly large and diverse population to permanently change a familiar behavior--and be excited about it. We asked ourselves: How are we going to convince more than a billion people to love passkeys as much as we do?" And once that's done, the data suggests there will be no turning back: * "Signing in with a passkey is three times faster than using a traditional password and eight times faster than a password and traditional MFA. * Users are three times more successful signing in with passkeys than with passwords (98% versus 32%). * 99% of users who start the passkey registration flow complete it." I like the three-step approach Microsoft sets out--start small through simple first steps, experiment with different approaches, and finally scale. ForbesiOS 18.2--iPhone Update Is Bad News For Millions Of Google Users By Zak Doffman "Even if we get our more than one billion users to enroll and use passkeys," Microsoft says, "if a user has both a passkey and a password, and both grant access to an account, the account is still at risk for phishing. Our ultimate goal is to remove passwords completely and have accounts that only support phishing-resistant credentials." The company offered password deletion back in 2022, and now reports that "millions of users have deleted their passwords." It's really that simple. You should use passkeys everywhere they're available. This ties the secure access to an account, app or service to the physical hardware you're using, which is protected by biometric access and a PIN code that is never shared or held off-device. It's more secure than 2FA even, given that most 2FA is SMS message based and can be intercepted by a rogue app on the device. Follow me on Twitter or LinkedIn. Zak Doffman Zak Doffman Following * Editorial Standards * Forbes Accolades Join The Conversation Comments One Community. Many Voices. Create a free account to share your thoughts. Read our community guidelines here. [community-] Forbes Community Guidelines Our community is about connecting people through open and thoughtful conversations. We want our readers to share their views and exchange ideas and facts in a safe space. In order to do so, please follow the posting rules in our site's Terms of Service. We've summarized some of those key rules below. Simply put, keep it civil. Your post will be rejected if we notice that it seems to contain: * False or intentionally out-of-context or misleading information * Spam * Insults, profanity, incoherent, obscene or inflammatory language or threats of any kind * Attacks on the identity of other commenters or the article's author * Content that otherwise violates our site's terms. User accounts will be blocked if we notice or believe that users are engaged in: * Continuous attempts to re-post comments that have been previously moderated/rejected * Racist, sexist, homophobic or other discriminatory comments * Attempts or tactics that put the site security at risk * Actions that otherwise violate our site's terms. So, how can you be a power user? * Stay on topic and share your insights * Feel free to be clear and thoughtful to get your point across * 'Like' or 'Dislike' to show your point of view. * Protect your community. * Use the report tool to alert us when someone breaks the rules. Thanks for reading our community guidelines. Please read the full list of posting rules found in our site's Terms of Service.